Unlock Your Salesforce Potential.






Solutions
Company
resources
Partners
Certifications & Compliance
Security questionnaires shouldn't require a discovery call. Below is the complete list of Flosum's certifications, audits, and framework alignments - what each one attests to, why it matters to you, and where the evidence lives. Audit reports and certificates are published in our documentation or available under NDA.
Book a Meeting →A common vendor trick is pointing at a cloud provider's certifications as if they were the vendor's. We don't. Flosum holds its own SOC 2 Type II covering Flosum's controls, policies, and operations. Our subprocessors - Salesforce and AWS - maintain their own independently audited programs, and each layer can produce its own report.
Covers Flosum's application, operations, personnel, and policies for both Cloud and Native products. Audited over a full period (Jan–Dec 2025), not a point in time. Available under NDA.
Provides its own SOC and ISO reports covering the Salesforce platform, where our native managed package runs. Available at compliance.salesforce.com.
Provides its own SOC and ISO reports covering the physical and virtualization infrastructure beneath Flosum-hosted Cloud Apps. Available via AWS Artifact.
A Type I says the right controls existed on one day. A Type II says an independent auditor watched those controls operate over months and verified they actually worked - the right policies, followed in practice, validated externally over time. When you assess Flosum, ask every vendor in your stack for the same: their own Type II, not their cloud provider's.
These attestations cover Flosum as an organization - its information security management, controls, and operations - validated by accredited third parties. Each card states what it is and why it should matter to your evaluation.
Trust Services Criteria - security, availability, processing integrity, confidentiality, and privacy - evaluated across a full audit period (Jan–Dec 2025), covering both Cloud and Native products.
An external auditor verified our controls operated effectively over twelve months. Point-in-time attestations can be staged; a Type II period cannot.
Information Security Management System. Independent certification that Flosum manages information security risk through structured policies, controls, and governance. Certificate published in our documentation.
Proves security is run as a management system with executive ownership, risk assessment, and continuous improvement - not a collection of ad-hoc tools.
Cloud-specific security controls: best practices and additional safeguards for protecting data in cloud services and multi-tenant environments.
ISO 27001 alone predates modern cloud risk. 27017 adds the cloud-specific controls - tenant isolation, virtual machine hardening, shared-responsibility clarity.
Protection of personally identifiable information (PII) in public clouds, with strict requirements for how personal data is stored and processed.
Your Salesforce data is full of PII. This certifies the specific controls governing how PII is handled in cloud processing - a frequent gap in vendor programs.
U.S. Department of Defense impact-level requirements for controlled unclassified information (CUI). Salesforce-native deployments running in Salesforce Government Cloud environments can support workloads at higher impact levels, including IL5.*
If you serve or sell to the DoD, your toolchain must match your data's impact level. Flosum's native architecture inherits the authorization of the government cloud it runs in.
Safeguards for protected health information (PHI), supporting customer compliance with U.S. healthcare privacy and security regulations.
DevOps and backup tooling touches production data - including PHI. A vendor without HIPAA safeguards makes your compliance officer's problem list longer, not shorter.
Controls and practices aligned with NIST federal cybersecurity guidance for threat detection, prevention, and response.
NIST 800-53 is the control language of the U.S. federal government and most mature security programs. Alignment means your assessors can map our controls directly to yours.
The highest standard for the secure processing and storage of payment card information.
If cardholder data exists anywhere in your Salesforce org, every tool that can read, back up, or migrate that org is in scope. Level 1 is the strictest tier there is.
Adherence to EU and U.S. data-privacy regulation, giving customers control over personal information, consent, and cross-border transfer.
Backup and migration tooling moves personal data by definition. GDPR/DPF adherence means lawful basis for transfer is our problem to document - not a gap you discover at renewal.
Corporate certifications tell you the organization is disciplined. Product-level evidence tells you the software you're deploying was tested. We publish both.
Flosum DevOps undergoes Checkmarx static code analysis. Reports are published in the security section of our documentation.
Flosum Backup & Archive is penetration-tested by independent third parties; pentest reports are available in our documentation.
The Salesforce-native managed package is distributed via AppExchange and subject to Salesforce's mandatory partner security review process.
Flosum-hosted services are audited every six months by reputable third parties. The AWS environment is continuously evaluated against AWS security best practices and monitored with CloudTrail and related AWS services.
Published statements covering system architecture, APIs, network security, authentication, data management, logging, patch management, data protection, risk management, incident response and disaster recovery, secure SDLC, and vendor risk management.
AES-256 at rest, TLS 1.2+ only in transit (TLS 1.0/1.1 and SSL disabled), AWS KMS-protected keys with a unique key per connected org - documented publicly, not asserted privately.
Certifications only mean something within their scope. Here is how scope works across Flosum's deployment architectures - stated plainly, because your auditors will ask.
A compliance page that only lists logos is marketing. One that tells you where each attestation starts and stops is documentation. If a vendor won't state the boundary of their SOC 2 scope, that is your first security finding.
ISO certificates, Flosum's SOC 2 Type II report, Checkmarx results, and pentest summaries are available in our documentation or under NDA. Subprocessor reports are available directly from Salesforce and AWS. Send your security questionnaire - we've answered harder ones.
No. Flosum buys out your remaining Own contract, so the switch can happen on your timeline — not your renewal date's.
No. We run both systems side by side until you have fully switched, so you're covered every single day of the transition.
Flat and constant — a number you can put in a budget and hold, no matter how fast your data grows. No usage-based surprises at renewal.
Yes. Flosum is built exclusively for Salesforce and designed for machine-scale change — automated full and incremental backups with granular, point-in-time restore for both data and metadata.
Thirty minutes: we review your current renewal quote, show you a live recovery, and give you a flat Flosum number to compare. No obligation.